Privacy + Secure Tech Corner Channel 🛡️
90 subscribers
6.66K photos
579 videos
530 files
16.2K links
Here you can find all about GSI's, ROM's, GKI Kernel's, Tech NEWS, Updates, Root methods, Magisk Module, Overlay's, Hacker things, FLOSS, FOSS, Privacy + Secure Stuff and many more!
Download Telegram
How Roaming Agreements Enable 5G MitM Attacks | media.ccc.de

End-users in cellular networks are at risk of connecting to fake base stations, and we show that mitigations pushed in 5G are insufficient.

Machine-in-the-Middle (MitM) attackers aim to overhear and manipulate network traffic. The MitM position can also be used as an entry point for baseband exploitation. Proceeding from there, attackers can gain full control of a user’s phone. Standardization bodies pushed many mitigations against MitM into the specification of cellular networks. However, roaming agreements still enable powerful attackers to perform seamless attacks – even in 5G!

In this talk, you’ll learn about the complex nature of cellular roaming and how roaming is implemented in recent smartphones. The specification puts a lot of trust in network operators. This impedes security in real-world deployments. We show that the capabilities of network operators exceed the intended capabilities of lawful interception. If those are abused, end-users have no possibility of noticing the attacks.

Attacks on roaming are challenging to prevent or even detect in practice. The specification needs a major update to make cellular roaming secure. Users at risk should be aware of the current state of the system. We discuss multiple mitigations, including solutions for end-user devices.

Licensed to the public under http://creativecommons.org/licenses/by/4.0

#Cellular #5g #Roaming
Oppo Pad 4 Pro
- World’s first Snapdragon 8 Elite tablet – AnTuTu score: 2,942,439
- Largest battery on a tablet: 12,140mAh
- HiFi-grade eight speakers
- Tiangong cooling system
Forwarded from Hacker News
Convert Linux to Windows
Article, Comments
Forwarded from Hacker News
Rust Adopting Ferrocene Language Specification
Article, Comments